feat(logout): improve logout flow

This commit is contained in:
Edouard Vanbelle
2026-08-09 14:09:54 +02:00
parent 321f3ad733
commit 2eb1e8a1d5
4 changed files with 37 additions and 10 deletions
+17
View File
@@ -17,3 +17,20 @@ export function getCsrfHeaders(): Record<string, string> {
const token = getCsrfToken();
return token ? { 'X-CSRF-Token': token } : {};
}
/**
* Best-effort "does the browser think it has a session?" hint. The server
* sets `oxicloud_csrf` (non-HttpOnly, JS-visible) alongside the session
* cookies on every login and clears it on logout, so its ABSENCE is a
* reliable proof of "no session" — cheaper than a network probe that
* would 401 → refresh 401 → 401 on first landing with no cookies.
*
* Its PRESENCE is only a hint: the session cookies (HttpOnly) may have
* been revoked server-side while the CSRF cookie lingers. Callers that
* see `true` must still probe /api/auth/me — this helper just lets a
* fresh no-cookie bootstrap skip the doomed 2× /me + /refresh burst.
*/
export function hasSessionHint(): boolean {
if (typeof document === 'undefined') return false;
return document.cookie.split('; ').some((row) => row.startsWith('oxicloud_csrf='));
}